For
a comprehensive list of things to do when setting up a new desktop or
server you may look at this Windows Security
Primer.
Forensic
and Vulnerability Tools- Foundstone has a complete set of tools
for testing and assessing your local network. Look under Resources
and then Free Tools. **Misuse of these tools can be
very serious. You may want to be cautious about using them outside
your local subnets as misuse can get you in trouble.**
Defensive Measures-
Defense
in Depth is the best approach to staying secure. You can look
for more information here.
SANS
Intrusion Detection FAQ's
What
to do if your system has been broken into or infected with a virus:
-
You must NOT ignore the system. Properly mark it so no one
else uses it.
-
If
you are not sure about it's behavior you should contact your local
support person for more assistance.
-
Your best
source of information about current worms, viruses or attacks will
be shown on NACS's home page.
-
If you are
sure your system has been infected or compromised then you should
disconnect it from the network.
-
Further
work can continue offline without causing issues for others on your
local network.
-
You should
verfiy that your system has been patched properly and it's antivirus
software is up to date.
-
If updates
are required then download them on another system and copy them
to a CD or floppy for transfer to the affected PC.
-
A system
that was taken over by an outside source ALWAYS needs to be formatted
and rebuilt.
-
Most of
todays viruses and worms leave back doors and holes to be exploited
later, so utmost consideration should be given to removing all data
from the system and formatting it. There is NO OTHER WAY in
most cases to clean a system so that reinfection doesn't occur.
-
All systems
need to be built offline with no network access. You may use
a desktop router to do this securely.
-
If there
is a possible problem with the affected system being subjected to
privacy
rules then please notify your local support group immediately!
|